Usable with caveats: the package is actively backed by an organization, has clear licensing, tests in the repository, and recent merged work. However, the repository shows no commits from maintainers in the last three months, and install-time scripts plus broad workflow permissions deserve review before adoption.
68%
Total Score
88
100
89
60
One workflow uses pull_request_target, which requires careful review because it can run with elevated repository context; no untrusted checkouts or script-injection patterns were detected.
The package runs post-autoload-dump and post-install-cmd scripts, increasing installation-time behavior and review requirements compared with a package without lifecycle hooks.
The package is 454 days old with five releases and one release in the last 12 months; the latest release is current, but the longer-term cadence is limited.
The repository records zero commits and zero active maintainers in the last three months, a significant maintenance concern, although six pull requests were merged in the last month and the repository was recently pushed.
The repository has only two stars, zero forks, and one watcher, so external adoption evidence is limited; this is supporting evidence rather than a decisive health failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^7.0|^8.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
kirschbaum-development/redactor Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.